{"id":965,"date":"2026-05-19T06:53:37","date_gmt":"2026-05-19T06:53:37","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=965"},"modified":"2026-05-19T06:53:37","modified_gmt":"2026-05-19T06:53:37","slug":"mini-shai-hulud-pushes-malicious-antv-npm-packages-via-compromised-maintainer-account","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=965","title":{"rendered":"Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjpyJDg_FqUDfeOeVX8IyhBHj9HqwkGZ-hV7b998CMLiBK2uPpmuQEN1cv1xYXJzRiznN6u_oXjA0lAGWgrkUH9EqaqfOFyW85ZQiz_Cr2YrHl1uxUHqEztt_iWG1LtRfNMpYTIqhS8vKTUOdZiNAf_r_g0r7LzqsvjmCmsr7_lv9jmXvHs5s76BEQCMnql\/s1700-e365\/npm-malware.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the ongoing Mini Shai-Hulud attack wave.<\/p>\n<p>\u00abThe attack affects packages tied to the npm maintainer account atool, including echarts-for-react, a widely used React wrapper for Apache ECharts with roughly 1.1 million weekly downloads,\u00bb Socket <a href=\"https:\/\/socket.dev\/blog\/antv-packages-compromised\">said<\/a>.<\/p>\n<p>The list of affected packages include @antv packages such as @antv\/g2, @antv\/g6, @antv\/x6, @antv\/l7, @antv\/s2, @antv\/f2, @antv\/g, @antv\/g2plot, @antv\/graphin, and @antv\/data-set, as well as related packages outside the @antv namespace, including echarts-for-react, timeago.js, size-sensor, canvas-nest.js, and others.<\/p>\n<p>The application security company said the tradecraft matches Mini Shai-Hulud, where a compromised maintainer account is leveraged to push out trojanized versions in quick succession.<\/p>\n<p>The development comes as the supply chain attack campaign continues to slither its way through the software supply chain, worming through different open-source registries rapidly and infecting hundreds of software packages by embedding credential-stealing code into popular development tools.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe potential blast radius is significant because the affected publishing account is connected to widely used packages across data visualization, graphing, mapping, charting, and React component ecosystems,\u00bb Socket said. \u00abEven if only a subset of those packages received malicious updates, the popularity of the package ecosystem creates meaningful downstream exposure for organizations that automatically pull new dependency versions.\u00bb<\/p>\n<p>The attacker is said to have published 639 malicious versions across 323 unique packages, including 558 versions across 279 unique @antv packages. The stealer payload harvests more than 20 credential types, Amazon Web Services, Google Cloud, Microsoft Azure, GitHub, npm, SSH, Kubernetes, Vault, Stripe, database connection strings, and attempts Docker container escape via the host socket. The stealer is identical to the Mini Shai-Hulud payload used in the SAP compromise.<\/p>\n<p>The collected data is eventually serialized, compressed, encrypted, and exfiltrated to the domain (\u00abt.m-kosche[.]com:443\u00bb). As a fallback mechanism, the malware leverages the stolen GitHub token to create a public repository under the victim&#8217;s account and commit the data in a JSON file.<\/p>\n<p>The repositories feature the description \u00abniagA oG eW ereH :duluH-iahS,\u00bb which reverses to \u00abShai-Hulud: Here We Go Again.\u00bb As of writing, there are more than <a href=\"https:\/\/github.com\/search?q=%22niaga%20og%20ew%20ereh%20%3Aduluh-iahs%22&amp;type=repositories\">2,200 repositories<\/a> in GitHub containing this marker.<\/p>\n<p>Furthermore, the malware incorporates an npm propagation logic that abuses the stolen npm tokens to first validate them through the npm registry API, enumerates packages maintained by the token owner, downloads package tarballs, injects the malicious payload, adds a preinstall hook, increases the package versions, and republishes them using the compromised maintainer&#8217;s identity.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiLS63DLKZxpgcQijf7gDgxTpqUZXdYou7KAOLE_1xdRtwkFfxDQ2NtitaxgWqrHMktV-QPZoMe4CZMhW-C8XfDbIgRowetsxexFKpW3TLh9vGF-hSy8-DNUk4CKO2lw_nAIQDVuEb-zDUld4RVAT26shg1hBLYt1PhJnMJoPh9-LuMYwLyKW7sXqyxJzuL\/s1700-e365\/Shai-Hulud-framework.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiLS63DLKZxpgcQijf7gDgxTpqUZXdYou7KAOLE_1xdRtwkFfxDQ2NtitaxgWqrHMktV-QPZoMe4CZMhW-C8XfDbIgRowetsxexFKpW3TLh9vGF-hSy8-DNUk4CKO2lw_nAIQDVuEb-zDUld4RVAT26shg1hBLYt1PhJnMJoPh9-LuMYwLyKW7sXqyxJzuL\/s1700-e365\/Shai-Hulud-framework.png\" alt=\"\" border=\"0\" data-original-height=\"1372\" data-original-width=\"2538\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">Shai-Hulud Framework<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00abThe attack uses two execution paths,\u00bb SafeDep <a href=\"https:\/\/safedep.io\/mini-shai-hulud-strikes-again-314-npm-packages-compromised\/\">said<\/a>. \u00abEach compromised version adds a preinstall hook (bun run index.js). 630 of the 631 malicious versions also inject an optionalDependencies entry [pointing to <a href=\"https:\/\/www.chainguard.dev\/unchained\/what-the-fork-imposter-commits-in-github-actions-and-ci-cd\">imposter commits<\/a>] that delivers a second copy of the payload via the legitimate antvis\/G2 GitHub repository.\u00bb<\/p>\n<p>\u00abThe 22-minute publish burst across 314 packages (631 versions), with an identical obfuscated payload, rules out a gradual or targeted operation. This was automated, rapid exfiltration using a stolen token.\u00bb<\/p>\n<p>The self-replicating Mini Shai-Hulud campaign is assessed to be the work of a financially motivated threat actor named TeamPCP. However, as of last week, the activity has entered an aggressive, new phase after TeamPCP <a href=\"https:\/\/slowmist.medium.com\/shai-hulud-malware-in-depth-analysis-open-source-means-loss-of-control-ca49cdc06bf7\">released the entire source code<\/a> for other threat actors to use as part of a supply chain attack contest announced in partnership with BreachForums.<\/p>\n<p>\u00abThe open-sourcing of a production offensive framework is not unprecedented, but it&#8217;s unusual for an active campaign,\u00bb Datadog <a href=\"https:\/\/securitylabs.datadoghq.com\/articles\/shai-hulud-open-source-framework-static-analysis\/\">said<\/a>. \u00abIt lowers the barrier for other actors to adopt TeamPCP&#8217;s playbook including the more sophisticated techniques like OIDC token abuse, provenance forgery, and AI tool persistence hooks.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Since then, an unknown threat actor has uploaded  four malicious npm packages  , one of which contains a near-verbatim copy of the Shai-Hulud worm with its own command-and-control infrastructure, an indication that cloned versions of the worm may infest open-source ecosystems.<\/p>\n<p>This <a href=\"https:\/\/mondoo.com\/blog\/shai-hulud-clones-arrive-when-worm-source-code-goes-open-source\">copycat wave<\/a>, in turn, complicates attribution efforts, while the attacks continue to facilitate credential theft and open the door for follow-on exploitation. The incident once again demonstrates how compromising tools that are already trusted inside enterprise networks can be abused as delivery vehicles for malware. What makes the campaign truly dangerous is that one compromise feeds into the next, resulting in an ever-expanding blast radius as more packages are hacked.<\/p>\n<p>\u00abThis campaign is built for credential theft at scale,\u00bb Trend Micro <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/e\/analyzing-teampcp-supply-chain-attacks.html\">said<\/a> in a report last week. \u00abOrganizations using GitHub Actions, PyPI, Docker Hub, GHCR [GitHub Container Registry], VS Code extensions, and cloud-connected CI runners are directly exposed to this risk.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the ongoing Mini Shai-Hulud attack&hellip;<\/p>\n","protected":false},"author":1,"featured_media":966,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[573,1718,227,1059,33,1618,39,35,932,1619],"class_list":["post-965","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-account","tag-antv","tag-compromised","tag-maintainer","tag-malicious","tag-mini","tag-npm","tag-packages","tag-pushes","tag-shaihulud"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/965","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=965"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/965\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/966"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=965"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=965"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}